Falcon LogScale Collector
| Typically Used By | Organizations with diverse log sources; Enterprises needing flexible log collection |
| Description | A versatile log collection agent that centralizes diverse log sources and provides advanced parsing and transformation capabilities before ingestion. |
| Official Vendor Documentation | https://library.humio.com |
| Setup Difficulty | 2 (Low) |
| Useful for | DevOps , SecOps |
| Primary Use Case | Centralized collection |
| Scenarios not Recommended | Small deployments with simple log requirements; Environments with severe resource constraints |
| Data Volume Handling | High |
| Authentication Method | Token-based |
| Fault Tolerance | High |
| Additional Tools Required | None |
Falcon LogScale Collector is CrowdStrike's native log shipper. It's a lightweight, purpose-built agent designed to collect log data from various sources on endpoints, servers, and containers, and forward it efficiently to Falcon LogScale Collector. The Collector supports multiple input methods including file tailing, Windows Event Logs, syslog reception, command execution, and container log collection. It provides built-in buffering, compression, and retry logic to ensure reliable data delivery even in challenging network conditions. As a native component of the Falcon LogScale Collector ecosystem, the Collector offers optimized performance, minimal resource footprint, and seamless integration with LogScale's parsing and ingestion capabilities.
Falcon LogScale Collector ingest flowThe following diagram shows how Falcon LogScale Collector log data flows through Log Collector's ingestion pipeline, highlighting specific parser types applied to the log data before data is compressed, stored in the repository, and indexed for searching:
Choose how to deploy the Collector
Full Install - this is CrowdStrike's recommended installation method. It supports Fleet version management and automatic Fleet enrollment.
Custom Install - install the Collector package and configure it manually on a supported Linux, Windows, or macOS host.
Kubernetes - deploy Falcon LogScale Collector using the CrowdStrike Helm chart for Kubernetes application/container logs.
Container image - CrowdStrike publishes a logscale-collector Docker image with Collector releases. It is Falcon LogScale Collector packaged as a container, not a separate "Docker Collector" product.
Before you begin
Identify the data source or sources that the Collector should read.
Identify the Falcon Log Collector repository or Falcon Next-Gen SIEM destination.
For a Log Collector sink, create or identify an ingest token for the destination repository.
Ensure the Collector can reach both the source and destination over the required network ports.
Decide whether the Collector will be locally configured or managed through Fleet Management.
Use a currently supported Collector release and review its release notes before deployment or upgrade.